IP Library › Granted Patent US 12,615,274
Granted Patent B2
US 12,615,274 · App. 18/611,178 · Granted Apr 28, 2026

Method and apparatus for determining compromised host

Inventor: Duo Yang (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,274
App. No.
18/611,178
Granted
Apr 28, 2026
Kind
B2
Abstract

This application discloses a method and an apparatus for determining a compromised host, and relates to the field of computer technologies. According to the method, a compromised host in a private network (or an intranet) can be accurately determined in a scenario in which the host in the private network (or the intranet) sends a packet via a NAT device. The method is applied to a security device deployed at a border between an external network and an internal network. The method includes: intercepting a file sent by the external network to the internal network, where the file is provided by a server of the external network based on a request of a target host of the internal network; determining a traceability probe file in response to the intercepted file being a malicious file; and sending the traceability probe file to the target host.

Claims (50)

1 . A method, comprising:

intercepting, by a security device, a first packet sent by an external network to an internal network, wherein the first packet comprises a sample file, wherein the security device is deployed at a border between the external network and the internal network, wherein the sample file is provided by a server of the external network based on a request of a target host of the internal network;

determining a traceability probe file in response to the sample file being a malicious file, wherein the traceability probe file controls a host running the traceability probe file to collect host information of the host and report the host information; and

sending the traceability probe file to the target host, wherein sending the traceability probe file to the target host comprises sending, to the target host, a second packet obtained by replacing the sample file transmitted in the first packet with the traceability probe file corresponding to the sample file.

2 . The method according to claim 1 , wherein before determining the traceability probe file, the method further comprises:

obtaining a traceability probe file library, wherein the traceability probe file library comprises a plurality of traceability probe template files of different types, wherein determining the traceability probe file comprises matching, in the traceability probe file library, a traceability probe template file whose file type is the same as that of the sample file, to obtain the traceability probe file.

3 . The method according to claim 2 , wherein matching, in the traceability probe file library, the traceability probe template file whose file type is the same as that of the sample file, to obtain the traceability probe file comprises:

generating a copy file of the traceability probe template file whose file type is the same as that of the sample file; and

renaming the copy file to a file name of the sample file, to obtain the traceability probe file.

4 . The method according to claim 1 , wherein the traceability probe file comprises address information of a target network device, the target network device comprises the security device, and the target network device is configured to receive the host information reported by the target host.

5 . The method according to claim 1 , wherein determining the traceability probe file comprises:

sending a traceability probe file obtaining request to a cloud device, wherein the cloud device determines the traceability probe file based on the traceability probe file obtaining request, the traceability probe file obtaining request comprises file information of the sample file, and the file information comprises a file name or a file type of the sample file; and

receiving the traceability probe file returned by the cloud device.

6 . The method according to claim 5 , wherein the traceability probe file comprises address information of a target network device, the target network device comprises the security device or the cloud device, and the target network device is configured to receive the host information reported by the target host.

7 . The method according to claim 4 , wherein when the target network device is the security device, the method further comprises:

determining an association relationship between the host information and the sample file.

8 . The method according to claim 1 , wherein the host information comprises address information of the target host, process information, gateway information, information about a user logging in to the target host, or information about time of collecting the host information.

9 . An apparatus, comprising:

a non-transitory memory storage comprising instructions; and

one or more processors in communication with the memory storage, wherein the one or more processors execute the instructions to:

intercept a first packet sent by an external network to an internal network, wherein the first packet comprises a sample file, wherein the apparatus is disposed in a security device deployed at a border between the external network and the internal network, wherein the sample file is provided by a server of the external network based on a request of a target host of the internal network;

determine a traceability probe file in response to the sample file being a malicious file, wherein the traceability probe file controls a host running the traceability probe file to collect host information of the host and report the host information; and

send the traceability probe file to the target host, wherein sending the traceability probe file to the target host comprises sending, to the target host, a second packet obtained by replacing the sample file transmitted in the first packet with the traceability probe file corresponding to the sample file.

10 . The apparatus according to claim 9 , wherein the instructions include further instructions to:

obtain a traceability probe file library before determining the traceability probe file, wherein the traceability probe file library comprises a plurality of traceability probe template files of different types, wherein the instructions to determine the traceability probe file include instructions to match, in the traceability probe file library, a traceability probe template file whose file type is the same as that of the sample file, to obtain the traceability probe file.

11 . The apparatus according to claim 10 , wherein the instructions to determine the traceability probe file include instructions to rename a copy file of the traceability probe template file whose file type is the same as that of the sample file to a file name of the sample file, to obtain the traceability probe file.

12 . The apparatus according to claim 9 , wherein the traceability probe file comprises address information of a target network device, the target network device comprises the security device, and the target network device is configured to receive the host information reported by the target host.

13 . The apparatus according to claim 9 , wherein the instructions include further instructions to:

send a traceability probe file obtaining request to a cloud device, wherein the cloud device determines the traceability probe file based on the traceability probe file obtaining request, the traceability probe file obtaining request comprises file information of the sample file, the file information comprises a file name or a file type of the sample file, and wherein the instructions to determine the traceability probe file include instructions to receive the traceability probe file returned by the cloud device.

14 . The apparatus according to claim 13 , wherein the traceability probe file comprises address information of a target network device, the target network device comprises the security device or the cloud device, and the target network device is configured to receive the host information reported by the target host.

15 . The apparatus according to claim 14 , wherein the instructions include further instructions to:

determine an association relationship between the host information and the sample file when the target network device is the security device.

16 . The apparatus according to claim 9 , wherein the host information comprises address information of the target host, process information, gateway information, information about a user logging in to the target host, or information about time of collecting the host information.

17 . A system, comprising:

a security device deployed at a border between an external network and an internal network, the security device comprising:

a non-transitory first memory storage comprising first instructions; and

one or more first processors in communication with the first memory storage, wherein the one or more first processors execute the first instructions to:

intercept a first packet sent by the external network to the internal network, wherein the first packet comprises a sample file, wherein the sample file is provided by a server of the external network based on a request of a target host of the internal network; and

send a traceability probe file obtaining request to a cloud device in response to the sample file being a malicious file, wherein the traceability probe file obtaining request comprises file information of the sample file, and the file information comprises a file name or a file type of the sample file; and

the cloud device, wherein the cloud device comprises:

a non-transitory second memory storage comprising second instructions; and

one or more second processors in communication with the second memory storage, wherein the one or more second processors execute the second instructions to:

receive the traceability probe file obtaining request;

determine a traceability probe file based on the file information carried in the traceability probe file obtaining request and a traceability probe file library; and

return the traceability probe file to the security device, wherein the traceability probe file controls a host running the traceability probe file to collect host information of the host and report the host information, and the traceability probe file library comprises a plurality of traceability probe template files of different types, wherein the first instructions comprise further instructions to receive the traceability probe file returned by the cloud device, and send the traceability probe file to the target host, and wherein sending the traceability probe file to the target host comprises sending, to the target host, a second packet obtained by replacing the sample file transmitted in the first packet with the traceability probe file corresponding to the sample file.

18 . The system according to claim 17 , wherein the first instructions include further instructions to receive the host information reported by the target host, and determine an association relationship between the host information and the sample file.

19 . The system according to claim 17 , wherein

the second instructions comprise further instructions to receive the host information reported by the target host, and determine an association relationship between the host information and the sample file; and

the first instructions comprise further instructions to obtain, from the cloud device, the host information and the file information of the sample file that have the association relationship.

20 . The system according to claim 17 , wherein the host information comprises at least one of address information of the target host, process information, gateway information, information about a user logging in to the target host, or information about time of collecting the host information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: YANG, DUO
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 066846/0461 →
Priority Claims (1)
CN 202111204369.0 · Oct 15, 2021 · national
Continuity (2)
Continuation PCTCN2022101653 · Jun 27, 2022
Related Publication 20240236132A1 · Jul 11, 2024
References Cited (28)
US 8145733B1 · Cheng · 2012 [cited by examiner]
US 9686304B1 · Guo · 2017 [cited by examiner]
US 12218968B1 · Harb · 2025 [cited by examiner]
US 20080229414A1 · Hudis · 2008 [cited by examiner]
US 20080229421A1 · Hudis · 2008 [cited by examiner]
US 20080229422A1 · Hudis · 2008 [cited by examiner]
US 20130205361A1 · Narayanaswamy · 2013 [cited by examiner]
US 20150264069A1 · Beauchesne · 2015 [cited by examiner]
US 20160226899A1 · Reddy · 2016 [cited by examiner]
US 20160359887A1 · Yadav · 2016 [cited by examiner]
US 20170180421A1 · Shieh · 2017 [cited by examiner]
US 20170302689A1 · Jiang · 2017 [cited by examiner]
US 20190081952A1 · Wood · 2019 [cited by examiner]
US 20190190929A1 · Thomas · 2019 [cited by examiner]
US 20190306185A1 · Katrekar · 2019 [cited by examiner]
US 20190312887A1 · Grimm · 2019 [cited by examiner]
US 20190327263A1 · Jalio · 2019 [cited by examiner]
US 20200304528A1 · Ackerman · 2020 [cited by examiner]
US 20200389487A1 · Zhauniarovich · 2020 [cited by examiner]
US 20210344690A1 · Sharifi Mehr · 2021 [cited by examiner]
US 20210344726A1 · Sharifi Mehr · 2021 [cited by examiner]
US 20220247785A1 · Ly · 2022 [cited by examiner]
US 20230006899A1 · Nechushtan · 2023 [cited by examiner]
US 20250233891A1 · Datar · 2025 [cited by examiner]
CN 101212338A · 2008 [cited by examiner]
CN 102769679A · 2012 [cited by applicant]
CN 109450690A · 2019 [cited by examiner]
Proxy server, https://zh.wikipedia.org/wiki/%E4%BB%A3%E7%90%86%E6%9C%8D%E5%8A%A1%E5%99%A8, Nov. 19, 2024, 3 pages (total pages 7 with English translation). [cited by applicant]